CVE-2026-0235
Prisma Browser: Access and Data Rule Bypass
Severity
Medium 5.8
CVSS 4.0
Exploited
Not listed
EPSS
0.001
1.5th percentile
Discovered by
Third party
Published by the vendor
Published
May 13, 2026
Assigned by palo_alto
Description
A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to bypass certain access and data control policies.
Weakness: CWE-754
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Prisma Browser | SASE / SSE / Secure Web | cna-assigner |
Vendor-reported affected versions (1)
- Palo Alto Networks · Prisma Browser
Credit
Palo Alto Networks thanks Tan Inn Fung, Yu Ann Ong, Zhang Bosen, Stan Leow and Sean Seah from the GovTech Cybersecurity Group
Vendor remediation
VERSION SUGGESTED SOLUTION Prisma Browser Upgrade to 146.16.6.165 or later.